Fake crypto AML checkers drain user wallets

Scammers impersonate AML checkers to trick users into connecting wallets or signing transactions that give attackers control of tokens and NFTs.

Scammers are impersonating anti-money-laundering screening tools to trick users into connecting wallets or approving signatures that give attackers access to funds, then remove tokens and NFTs from compromised accounts.

Security teams and community moderators report a rise in cloned websites, fraudulent browser extensions and pop-up wallet-connect requests on social platforms and marketplaces. The fake services present themselves as address-screening tools and prompt users to approve transactions or paste private keys.

The activity has increased in recent weeks across multiple chains, including Ethereum, Binance Smart Chain and Polygon. Incidents occur where users interact with peer-to-peer marketplaces, social platforms and decentralized finance interfaces.

The scams follow a common pattern: a user is asked to verify a counterparty or an NFT using an online “AML checker.” After clicking a link or connecting a wallet, a transaction approval or signature window appears. Instead of a harmless signature the approval can grant a smart contract permission to move tokens or NFTs, or the user is asked to reveal seed phrases or private keys. Once permission or keys are obtained, attackers execute transfers and empty the wallet.

Fraudulent domains and wallet interfaces are frequently visually identical to legitimate services, which increases the chance users will accept the prompt. Targets include retail traders, NFT collectors and DeFi users trying to verify a seller, confirm provenance or show that a wallet is “clean.” Reported losses range from individual token balances to high-value NFTs and access to wallets holding larger portfolios.

Two common user actions are abused: signing messages and approving smart-contract allowances. A signature framed as an identity confirmation can, depending on content, authorize transactions or interactions with a malicious contract. Token approvals let a contract move tokens from a wallet repeatedly without further confirmations if users grant broad allowances.

Legitimate AML checkers exist to screen addresses against sanctions lists, flagged accounts and known scams. Those services normally display clear branding, use documented APIs and follow established security practices. Attackers copy visual elements or pose as lesser-known screening sites that promise instant clearance for trading.

Security teams recommend verifying domains, checking official links from exchanges or marketplaces, and avoiding pasting private keys or seed phrases into websites. On-chain allowances can be inspected and revoked through reputable tools that list which contracts have permission to move tokens. Wallet providers and marketplaces have been urged to add clearer warnings about signing requests and to vet third-party integrations.

“They mimic the look of real checkers to trick users into approving dangerous transactions,” a security researcher observed.

Users who suspect a fake checker should disconnect wallets, revoke suspicious approvals and report cloned domains, extensions or posts to platform moderators.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author